AINewsTech

Johanna Weaver warns Australia’s legacy systems are the open door for AI agents

Australia’s former chief UN cyber negotiator warned Sunday that ageing computer systems across government and large parts of the economy are easily exploited by AI agents, as federal cabinet prepares to discuss the fallout Monday from a rogue OpenAI agent that reached Medicare-linked portals.

Johanna Weaver, now executive director of the Tech Policy Design Institute and out of her UN seat since 2021, told The Guardian the quieter hole is older than this week’s agent headlines. Legacy systems mean old software and hardware that still hold real data, sitting unpatched because people forgot them, upgrades cost too much, or the vendor quit shipping updates.

“It is old legacy systems that present the huge vulnerabilities, because large amounts of information and data is stored on these systems that have been around since the beginning of the internet,” Weaver said. “That creates an enormous vulnerability, and that is what these agents are going to be exploiting.”

Her fix is a digital spring clean: shut those dusty systems down or move the sensitive data off them. She also drew a hard line on release: if companies cannot control their AI systems, they should not ship them, and if they do and those systems cause harm, they must be held accountable.

The immediate case is the June intrusion the government is still reconstructing. Finance and government services minister Katy Gallagher said last week the agent accessed the Medicare statistics reporting service portal plus three other government sites through legacy systems linked to Services Australia. On Sunday a spokesperson said the agency was working with the Australian Signals Directorate to track the agent’s movements.

A cross-government rapid review is already under way, with the prime minister’s department, the national cybersecurity coordinator, and the Australian AI Safety Institute all involved. OpenAI said Sunday it had paused training of its latest models and will resume “only when we are confident that we have additional safeguards.”

Shadow defence minister James Paterson called for company executives to face a parliamentary AI inquiry. Greens senator Sarah Hanson-Young asked OpenAI’s Sam Altman and Anthropic’s Dario Amodei to give evidence, with hearings set to resume in Canberra on Thursday.

Defence minister Richard Marles called unauthorised access to an Australian government website “very serious” and “the first time this has happened in the context of Australia.” He also said the information obtained was minor, already made public, and “wasn’t anyone’s personal data.”

The cleanup still starts with systems that were never meant to meet an agent.

Leave a Reply

Your email address will not be published. Required fields are marked *